Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

644 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.37%—Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI30/7/202630/7/2026
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request.
AplazadaAlta (7.1)0.25%—Themefic Ultimate Addons FOR Contact Form 7AI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
AplazadaAlta (7.2)0.27%—Peprodev Ultimate InvoiceAI23/7/202623/7/2026
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
AplazadaAlta (7.1)0.25%—Peprodev Ultimate InvoiceAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
AplazadaMedia (5.3)0.33%—Ultimate Store KIT Elementor AddonsAI23/7/202623/7/2026
Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
AplazadaMedia (6.5)0.22%—Ultimate Store KIT Elementor AddonsAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
AplazadaMedia (6.5)0.27%—Peprodev Ultimate InvoiceAI23/7/202623/7/2026
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
AplazadaMedia (6.5)0.37%—Peprodev Ultimate InvoiceAI23/7/202623/7/2026
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
AplazadaMedia (6.4)0.42%—Brainstormforce Ultimate Addons FOR ElementorAI22/7/202622/7/2026
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (5.4)0.23%—Ultimate Before After Image Slider AND GalleryAI14/7/202629/9/2026
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode content verbatim), allowing users with administrator-level…
ModificadaAlta (8.8)0.50%💥 PoCOllyo Helix Ultimate13/7/202623/7/2026
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
ModificadaAlta (8.7)0.25%💥 PoCOllyo Helix Ultimate13/7/202623/7/2026
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
AplazadaAlta (8.8)1.1%—Smackcoders WP Ultimate CSV ImporterAI11/7/202613/7/2026
The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and…
AplazadaMedia (4.4)0.24%—WP Ultimate CSV Importer Infinite Scroll Ajax Load MoreAI10/7/202614/7/2026
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AplazadaAlta (7.5)0.51%—Ultimatemember Ultimate MemberAI10/7/202610/7/2026
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to insufficient escaping on the user supplied parameter and lack of…
AplazadaMedia (6.4)0.36%—Ultimate PostAI9/7/20269/7/2026
The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/advanced-search block in versions up to and including 5.0.31. This is due to insufficient input sanitization and output escaping in the Advanced_Search::content() render…
AplazadaAlta (8)0.41%—Ultimatemember Ultimate MemberAI6/7/20266/7/2026
The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript that executes when any user, including an administrator,…
AplazadaMedia (6.4)0.42%—Ultimatemember Ultimate MemberAI3/7/20266/7/2026
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'about_me' parameter in all versions up to, and including, 2.11.4 due to insufficient input sanitization and output escaping. This…
AplazadaAlta (8.8)0.72%—Ultimatemember Ultimate MemberAI24/6/202625/6/2026
The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.11.4. This is due to a chain of three logic bugs: (1) an MD5 hash fallback in get_directory_by_hash() that allows any post to be used as a member directory by computing…
AplazadaAlta (7.1)0.25%—Ultimate Woocommerce Auction PROAI22/6/202622/6/2026
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaMedia (6.1)0.25%—Ultimate-woocommerce-auction-pro Ultimate Woocommerce Auction PROAI22/6/202622/6/2026
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaCrítica (9.3)0.80%—Brainstormforce Ultimate Addons FOR Beaver BuilderAI20/6/202629/9/2026
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a…
AnalizadaAlta (8.8)0.43%—Faboba Ultimate Property Listing19/6/202619/8/2026
Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_selectuser_id parameter. Attackers can send GET requests to index.php with the option=com_upl and view=propertylisting…
AplazadaAlta (8.5)0.35%—Effress Woocommerce Frontend Manager UltimateAI17/6/202617/6/2026
Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.
AplazadaAlta (8.7)0.32%—Wpultimate Wordpress Ultimate Product CatalogAI15/6/202617/6/2026
WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Products tab custom file…
Orbitaley — Vulnerabilidades